A former Region Östergötland employee has been convicted of unlawful data access (dataintrång) for opening 129 patient records with no work reason. The district court handed down a conditional sentence and ordered SEK 288,000 in damages to 36 patients, SVT Nyheter reported on 6 October.
Corren identifies her as an administrator at the psychiatric clinic in Linköping. Between 11 November 2022 and 9 May 2023 she went into Cosmic, the region’s patient record system, 129 times and read about roughly 100 patients. Some were acquaintances, others complete strangers. The notes she read covered gynaecological visits, grief counselling and addiction.
She admitted the offences and told the court she was curious. One of the records was her own. According to the judgment, she did not pass the information on.
Found In the Region’s Own Log Checks
Region Östergötland’s log checks uncovered the access and the court relied on the system logs and the region’s internal investigation alongside her confession, SVT reports. A source with insight into the case whom Corren did not name, says she was dismissed the same day it was discovered in May 2023. She was also reported to the police.
Patientdatalagen forbids anyone working for a care provider from reading a patient’s record unless the care work requires it. That includes their own record and their relatives’. Socialstyrelsen’s regulations, HSLF-FS 2016:40, require care providers to run systematic and recurring sample checks of the access logs.
The checks caught her six months after the first look-up by which point she had made 129 of them.
IMY ordered tighter Cosmic access in 2020
In December 2020, Datainspektionen, now IMY, found that the region had not carried out the needs and risk analysis the law requires before staff are given access to Cosmic. It ordered the region to complete that analysis and then give each user individual access based on it and imposed a SEK 2.5 million administrative fine.
The snooping began less than two years later. Neither SVT nor Corren reports anything from the verdict on what access a psychiatric clinic administrator held or why she could open those records at all.
Three More Convictions This Year
Östersunds tingsrätt has convicted a medical secretary in Jämtland of 17 counts of dataintrång for logging in to a relative’s record with no care relationship, Östersunds-Posten reported on 7 October. The court imposed day-fines.
In Skara, a 40-year-old woman was convicted in May of 53 counts covering December 2020 to May 2023. That case came to light only after one of the victims reported that private details had spread according to Lidköpingsnytt.
In March, Skaraborgs tingsrätt gave a Lidköping nurse a conditional sentence for opening 150 records. Most of her 16 victims were awarded SEK 8,000 each, according to Nya Lidköpings-Tidningen. Each of the 36 Östergötland patients receives the same amount plus interest.
In all four cases the records had already been read by the time anyone noticed and in Skara it took a victim to raise the alarm. For a healthcare CISO we would start with access rights rather than logs. Pick one administrative role, pull every record it opened last month and count how many had a care relationship behind them.
References
- Döms för dataintrång i 129 patientjournaler
- Vårdanställd döms: gick in i patienters journaler 129 gånger
- Tillsynsbeslut mot Region Östergötland, DI-2019-3843
- Patientdatalag (2008:355)
- HSLF-FS 2016:40 om journalföring och behandling av personuppgifter i hälso- och sjukvården
- Sekreterare döms för dataintrång
- Öppnade patientjournaler 53 gånger utan skäl
- Sjuksköterska döms för massivt dataintrång i Lidköping
This post is also available in:


